lists.openwall.net   lists  /  announce  john-users  owl-users  popa3d-users  /  xvendor  oss-security  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4 
Open Source and information security mailing list archives
 
Order Openwall GNU/*/Linux 2.0 on a CD with delivery worldwide
[<prev] [next>] [<thread-prev] [thread-next>] [month] [year] [list]
Date:	Mon, 01 Jan 2007 23:51:32 -0800 (PST)
From:	David Miller <davem@...emloft.net>
To:	m.kozlowski@...land.pl
Subject: Re: [PATCH] net: ifb error path loop fix

From: Mariusz Kozlowski <m.kozlowski@...land.pl>
Date: Tue, 2 Jan 2007 00:55:51 +0100

> On error we should start freeing resources at [i-1] not [i-2].
> 
> Signed-off-by: Mariusz Kozlowski <m.kozlowski@...land.pl>

Patch applied, thanks Mariusz.

> diff -upr linux-2.6.20-rc2-mm1-a/drivers/net/ifb.c linux-2.6.20-rc2-mm1-b/drivers/net/ifb.c
> --- linux-2.6.20-rc2-mm1-a/drivers/net/ifb.c	2006-12-24 05:00:32.000000000 +0100
> +++ linux-2.6.20-rc2-mm1-b/drivers/net/ifb.c	2007-01-02 00:25:34.000000000 +0100
> @@ -271,8 +271,7 @@ static int __init ifb_init_module(void)
>  	for (i = 0; i < numifbs && !err; i++)
>  		err = ifb_init_one(i);
>  	if (err) {
> -		i--;
> -		while (--i >= 0)
> +		while (i--)
>  			ifb_free_one(i);
>  	}

One could argue from a defensive programming perspective that
this bug comes from the fact that the ifb_init_one() loop
advances state before checking for errors ('i' is advanced before
the 'err' check due to the loop construct), and that's why the
error recovery code had to be coded specially :-)

Anyways, your fix is of course fine and I've applied it.
-
To unsubscribe from this list: send the line "unsubscribe netdev" in
the body of a message to majordomo@...r.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html

Hosted by DataForce ISP - Powered by Openwall GNU/*/Linux